Quality of security metrics and measurements

被引:34
|
作者
Savola, Reijo M. [1 ]
机构
[1] VTT Tech Res Ctr Finland, Oulu 90650, Finland
关键词
Security metrics; Security quantification; Quality of security metrics; Expert opinion survey; Security effectiveness;
D O I
10.1016/j.cose.2013.05.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Quantification of information security can be used to obtain evidence to support decision-making about the security performance of software systems. Knowledge about the relational importance of the main quality criteria of security metrics can help build security metrology models based on practical needs. This paper presents the results of a quantitative security metrics expert survey of 141 respondents, and an associated interview study, regarding the prioritization of 19 quality criteria of security metrics identified in the literature. The interviews were used to validate the survey results and to obtain further information on the findings. The results identified three foundational quality criteria of security metrics: correctness, measurability, and meaningfulness. These criteria form the basis for credibility and sufficiency for security metrics and associated measurements. Moreover, usability was seen as an important criterion. The paper analyzes the foundational and related quality criteria and proposes a model of them. (c) 2013 Elsevier Ltd. All rights reserved.
引用
收藏
页码:78 / 90
页数:13
相关论文
共 50 条
  • [1] Security measurements and metrics for networks
    Holz, Thorsten
    [J]. DEPENDABILITY METRICS: ADVANCED LECTURES, 2008, 4909 : 157 - 165
  • [2] COMPUTER SOFTWARE QUALITY MEASUREMENTS AND METRICS
    SHERIF, YS
    NG, E
    STEINBACHER, J
    [J]. MICROELECTRONICS RELIABILITY, 1985, 25 (06) : 1105 - 1150
  • [3] Taxonomy of quality metrics for assessing assurance of security correctness
    Moussa Ouedraogo
    Reijo M. Savola
    Haralambos Mouratidis
    David Preston
    Djamel Khadraoui
    Eric Dubois
    [J]. Software Quality Journal, 2013, 21 : 67 - 97
  • [4] Taxonomy of quality metrics for assessing assurance of security correctness
    Ouedraogo, Moussa
    Savola, Reijo M.
    Mouratidis, Haralambos
    Preston, David
    Khadraoui, Djamel
    Dubois, Eric
    [J]. SOFTWARE QUALITY JOURNAL, 2013, 21 (01) : 67 - 97
  • [5] Using Security Metrics in Software Quality Assurance Process
    Abdi, Athena
    Souzani, Afshin
    Amirfakhri, Maliheh
    Moghadam, Azadeh Bamdad
    [J]. 2012 SIXTH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2012, : 1099 - 1102
  • [6] ARIMA Supplemented Security Metrics for Quality Assurance and Situational Awareness
    Kohlrausch, Jan
    Brin, Eugene A.
    [J]. DIGITAL THREATS: RESEARCH AND PRACTICE, 2020, 1 (01):
  • [7] Metrics for the quality of footprint-matched passive microwave measurements
    Galantowicz, JF
    [J]. IGARSS 2004: IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM PROCEEDINGS, VOLS 1-7: SCIENCE FOR SOCIETY: EXPLORING AND MANAGING A CHANGING PLANET, 2004, : 3763 - 3766
  • [8] COMPUTER SOFTWARE-DEVELOPMENT - QUALITY ATTRIBUTES, MEASUREMENTS, AND METRICS
    SHERIF, YS
    NG, E
    STEINBACHER, J
    [J]. NAVAL RESEARCH LOGISTICS, 1988, 35 (03) : 425 - 436
  • [9] Security Metrics Foundations for Computer Security
    Trcek, Denis
    [J]. COMPUTER JOURNAL, 2010, 53 (07): : 1106 - 1112
  • [10] Security Metrics and Security Investment Models
    Boehme, Rainer
    [J]. ADVANCES IN INFORMATION AND COMPUTER SECURITY, 2010, 6434 : 10 - 24